Updated

Data Processing Agreement

The data processing agreement between Querly and its business customers, under Article 28 GDPR, for the call data Querly processes.

This Data Processing Agreement ("DPA") is part of the Terms of Service between L&T Studio V.O.F., trading as Querly, established in Castricum, the Netherlands, KvK 98045075 ("Querly", the processor; contact details on our contact page), and the business that subscribes to Querly ("the customer", the controller). It applies when Querly processes personal data on the customer's behalf, and meets Article 28 of the General Data Protection Regulation (GDPR).

1. Roles

The customer decides in which calls it uses Querly and for what purpose, and is the controller of the personal data in those calls. Querly processes that data only to provide the Querly service and is the processor. Querly is controller for its own records about the customer: the account and billing details, the devices signed in, and the record of requests and call hours on Querly's server; see our privacy statement.

2. What is processed

  • Subject matter and purpose: providing Querly: transcribing calls live, suggesting questions, preparing briefings and summaries, and learning the user's question style.
  • Duration: for as long as the subscription runs, and afterwards as set out in section 10.
  • Categories of data subjects: the customer's users, and the people they talk to in calls (for example the customer's clients and prospects).
  • Types of personal data: voices and speech in calls, the transcript of what was said, names and other details mentioned in a call, the goal, checklist and line about the other party the user writes, the questions shown, summaries, and the user's learned question style (including up to six example questions the user asked).
  • Special categories: Querly is not intended for them (see section 4 of the Terms of Service). Querly does not create or store voiceprints: speakers are told apart only within a single call, by the speech recognition provider, and that labelling is not kept to recognise people across calls.

3. How the processing works

  • The Querly app runs on the user's own computer. It reaches the providers through Querly's server in Germany, which holds Querly's accounts with them. The server doesn't store call content. Its records of requests and call hours are Querly's own (section 1).
  • During a call, the app streams the call audio over an encrypted connection directly to the speech recognition provider, Soniox, in its EU region, with short-lived keys from Querly's server; the audio doesn't pass through that server. The transcript text, the goal, checklist and line about the other party, and the user's question style go over encrypted connections through Querly's server to the language model hosts. These providers are the subprocessors on our subprocessors page.
  • The briefing before a call is made by Anthropic from the goal or checklist, the line about the other party, the language and the number of participants. It never receives the call audio or the transcript.
  • Meeting records are stored on the user's computer, and the app deletes them as follows:
  • The meeting note, with its transcript, stays until the user deletes it. In the app's privacy settings the user can set a period instead (30, 90, 180 or 365 days); the app then deletes older meeting notes itself.
  • The working files of a call (the transcript segments, the questions, what the language models were sent and answered, the summary and the briefing) are deleted 30 days after the call.
  • Briefings made before calls, and the list of calls the question style learned from (date, length and goal), are deleted after 30 days.
  • The learned question style is a short description of how the user phrases questions, with up to six example questions the user asked. It is kept until the user resets it in the app, and is sent with each call to the language model that writes the questions.
  • The app's diagnostic log files are only written when the user turns on debug logging. They leave out the transcript and the questions; every text in them is cut to 200 characters, so an error message can quote at most that much of a language model's answer. They are deleted after 14 days.
  • Settings in the app (the goals, the line about the other party and the templates the user typed) stay until the user changes or deletes them.
  • Deleting a note deletes its transcript, its working files and its briefing.

4. Querly's obligations

Querly:

  1. processes the personal data only on the customer's documented instructions, which are this DPA, the Terms of Service and the customer's use of the app's settings, including with regard to transfers of personal data to a third country, unless EU or Dutch law requires otherwise, in which case Querly tells the customer first unless the law forbids it;
  2. makes sure that everyone at Querly who has access to the data is bound to confidentiality;
  3. takes the technical and organisational measures in section 7;
  4. engages subprocessors only as set out in section 5;
  5. helps the customer, as far as it reasonably can, to respond to requests from data subjects exercising their rights;
  6. helps the customer meet its obligations on security, data breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR), taking into account the information available to Querly;
  7. at the end of the service, at the customer's choice, deletes or returns the data as set out in section 10;
  8. gives the customer the information needed to show compliance with Article 28 GDPR and allows for and contributes to audits as set out in section 9;
  9. tells the customer immediately if, in its opinion, an instruction infringes the GDPR.

5. Subprocessors

The customer gives general authorisation for Querly to engage subprocessors. The current subprocessors are on our subprocessors page. Querly informs the customer by email at least 30 days before adding or replacing a subprocessor. The customer may object on reasonable grounds within that period; if we can't resolve the objection, the customer may end the subscription with a refund of the unused part of the period. Querly imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible for their performance.

6. Transfers outside the EEA

Some subprocessors process data in the United States: the language model hosts (OpenRouter, DeepInfra and Together AI) and Anthropic. Call audio and transcripts at Soniox stay in its EU region. For Anthropic, Querly relies on the European Commission's standard contractual clauses in Anthropic's data processing addendum, which is part of its commercial terms. For OpenRouter, which passes requests on to DeepInfra and Together AI under written agreements, Querly relies on the standard contractual clauses in OpenRouter's data processing agreement, which is part of its terms of service.

7. Security measures

  • All data sent from the app to subprocessors travels over encrypted connections (TLS).
  • The app holds no provider keys: they are kept only on Querly's server. The app's sign-in token is stored encrypted (AES-256, with the key in Windows Credential Manager); the server keeps only a hash of each token and of each sign-in code, allows five tries per code, and lets a device be signed out at once.
  • Querly's server accepts only HTTPS (with HSTS), keeps no access logs, limits requests per device and AI spending per customer, and is backed up daily, with backups kept 30 days.
  • The question window is excluded from screen capture, so questions don't appear when the user shares their screen.
  • Querly has no servers that store call data, which limits what can be exposed at Querly.
  • Language model requests from the app go through Querly's server, which allows only the models the app uses and forces every request to the hosts DeepInfra and Together AI, with zero data retention, data collection denied and no fallback to other hosts. It removes options that would send the text elsewhere, such as web search.
  • The customer is responsible for the security of its own computers, where meeting records are stored.

8. Personal data breaches

Querly notifies the customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the customer's data. The notice describes what is known about the nature of the breach, the data and people affected, the likely consequences, and the measures taken or proposed. Querly keeps the customer informed as more becomes known.

9. Information and audits

Querly makes available all information necessary to show compliance with this DPA. The customer may have an audit carried out, at its own cost, by an independent auditor bound to confidentiality, no more than once a year and with at least 30 days' notice, unless a breach gives reason for more. Querly may first offer relevant reports or certifications of itself and its subprocessors.

10. End of the processing

Because meeting records are stored on the customer's own computers, the customer keeps and can delete them itself. Querly's server holds no call content. Within 30 days after the subscription ends, Querly deletes or, at the customer's choice, returns any call data it still holds for the customer, unless EU or Dutch law requires it to keep it, and confirms this on request. Querly's own account and billing records are kept as described in our privacy statement. Subprocessors delete data under their own retention periods, listed on the subprocessors page.

11. Liability and order of precedence

The liability provisions of the Terms of Service apply to this DPA, to the extent the GDPR allows. If this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails.

12. Law

Dutch law applies to this DPA. Disputes go to the competent court in the district of Noord-Holland, the Netherlands.